An alleged leader of the notorious global hacking syndicate ShinyHunters has been arrested in the Netherlands following a joint operation between the FBI and Dutch authorities, targeting a cybercrime network linked to high-profile attacks across the U.S. and worldwide.
Dutch police announced the arrest of a 24-year-old Amsterdam man Sept. 15 for his alleged role in the ShinyHunters hacking group and for attempting to incite two murders, with authorities noting that further arrests remain possible as they investigate seized electronic devices.
"This morning @FBI and our partners the Dutch National Police are announcing the arrest of one of the alleged leaders of ShinyHunters – a global cybercrime and threat actor group linked to cyberattacks in the United States, the Netherlands, and around the world," FBI Director Kash Patel wrote Tuesday morning on X.

FBI Director Kash Patel says "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation." (Anna Moneymaker/Getty Images; Graeme Sloan/Bloomberg via Getty Images)
"In coordination with FBI investigators the Dutch High-Tech Crime Unit arrested the suspect under Dutch law. As we speak FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest.
"Thank you to our Dutch National Police partners for their continued work with us in this case and the industry partners who shared information with us. The investigation continues."
"The man is also suspected of attempted incitement to commit two murders," according to a Dutch police release. "Various data carriers have been seized and are being investigated further. Further arrests are not ruled out."
Brett Leatherman, assistant director of the FBI's Cyber Division, made an unusually public address to the hacking group ShinyHunters, telling the cybercriminals that "we know how to find you."

ShinyHunters listed the State of Florida DMV on its leak site and threatened to release allegedly stolen files if the agency did not respond. (BleepingComputer)
"To the remaining members of ShinyHunters: You've heard about the arrest of your colleague," Leatherman's video statement warned. "We're confident you've seen or heard things in recent days that the public has not.
"Other groups believed anonymity or their friends would protect them, and they were wrong. Arrests have a way of changing who is willing to talk. And seized infrastructure has a way of showing us who's left.
"The longer you stay in this, the more we learn about you. You know how to find us and we know how find you. I suggest you reach out first while the choice is still yours."
Benjamin Korper of Amsterdam-based cybersecurity company Neo Security named the arrested man as Pepijn van der Stap, the company's offensive security lead.
"Since last year, this cyber criminal and his co-conspirators have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments," Leatherman said in his video statement, which did not name the suspect. "They often target third-party vendors and cloud-based platforms, stealing sensitive data in extorting victims with threats to publish it."
In a telephone interview with Reuters, Korper said Dutch forensic investigators visited his office Sept. 15, the night Van der Stap was arrested in a dramatic police raid that involved flash bang grenades.
ShinyHunters is a hacking group known for large-scale data breaches and extortion and had announced its recent theft of what it said was terabytes of sensitive personnel data from U.S. FBI servers, including intelligence assignments and medical records of employees, according to Reuters.
An internal memo circulated to staffers said the FBI was operating under the presumption that hackers stole data pertaining to all bureau employees, a source told Reuters.
In a statement, ShinyHunters said Van der Stap had "no association" with the group and that Dutch police were incompetent.
News of Van der Stap's arrest caused a stir in the cybersecurity community.
Van der Stap's 2023 convictions of data theft and extortion had already received widespread publicity, as did his subsequent public disavowal of cybercrime. On his personal website, Van der Stap acknowledged his journey "hasn't been a straight line" but said his experience had taught him that "knowledge is for building and protecting, not breaking."
Korper said he had carefully vetted Van der Stap before hiring him, monitored him during his employment, and was shocked by the arrest.
"I truly believe that people deserve a second chance, but in this case I was not thanked for it," Korper said. "Absolutely everybody I talked to is flabbergasted."
The executive said he had hired an outside firm to investigate whether Van der Stap had hacked Neo Security or its customers, but so far investigators have found no evidence that he acted against his employer or its clients.
Korper and Van der Stap have not been in touch since the arrest, Korper said.

8 hours ago
42









English (US) ·